İçeriğe atla
Noroxi

properfraction kayıtları

properfraction üreticisine ait 35 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%42,9
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

35 kayıt
  • CVE-2021-34621
    60Bu hafta

    ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation

    KritikCVSS 9,8Kavram kanıtıEPSS %69

    properfraction · profilepress7 Tem 2021

  • CVE-2021-34624
    41Planlayın

    ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader Component

    KritikCVSS 9,8Kavram kanıtıEPSS %7

    properfraction · profilepress7 Tem 2021

  • CVE-2021-34623
    40Planlayın

    ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in Image Uploader Component

    KritikCVSS 9,8İstismar yokEPSS %2

    properfraction · profilepress7 Tem 2021

  • CVE-2024-9947
    39İzleyin

    ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider

    KritikCVSS 9,8İstismar yokEPSS %1

    properfraction · profilepress23 Eki 2024

  • CVE-2021-34622
    36İzleyin

    ProfilePress 3.0 - 3.1.3 - Authenticated Privilege Escalation

    YüksekCVSS 8,8Kavram kanıtıEPSS %4

    properfraction · profilepress7 Tem 2021

  • CVE-2023-41954
    34İzleyin

    WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerability

    YüksekCVSS 8,6Kavram kanıtıEPSS %1

    properfraction · profilepress17 May 2024

  • CVE-2023-44150
    30İzleyin

    WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data Exposure

    YüksekCVSS 7,5İstismar yokEPSS %1

    properfraction · profilepress30 Kas 2023

  • CVE-2022-45083
    28İzleyin

    WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injection

    YüksekCVSS 7,2İstismar yokEPSS %1

    properfraction · profilepress19 Oca 2024

  • CVE-2021-24522
    24İzleyin

    ProfilePress < 3.1.11 - Unauthenticated Cross-Site Scripting (XSS) in tabbed login/register widget

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    properfraction · profilepress9 Ağu 2021

  • CVE-2024-1519
    24İzleyin

    Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.4 - Unauthenticated Stored Cross-S

    OrtaCVSS 6,1İstismar yokEPSS %1

    properfraction · profilepress28 Şub 2024

  • CVE-2023-23830
    24İzleyin

    WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)

    OrtaCVSS 6,1İstismar yokEPSS %0

    properfraction · profilepress3 May 2023

  • CVE-2022-47444
    24İzleyin

    WordPress ProfilePress Plugin <= 4.4.1 is vulnerable to Cross Site Scripting (XSS)

    OrtaCVSS 6,1İstismar yokEPSS %0

    properfraction · profilepress29 Mar 2023

  • CVE-2024-1408
    21İzleyin

    ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode

    OrtaCVSS 5,4İstismar yokEPSS %1

    properfraction · profilepress28 Şub 2024

  • CVE-2024-1535
    21İzleyin

    ProfilePress <= 4.15.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    OrtaCVSS 5,4İstismar yokEPSS %1

    properfraction · profilepress13 Mar 2024

  • CVE-2024-1806
    21İzleyin

    ProfilePress <= 4.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcode

    OrtaCVSS 5,4İstismar yokEPSS %1

    properfraction · profilepress13 Mar 2024

  • CVE-2023-50882
    21İzleyin

    WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerability

    OrtaCVSS 5,3İstismar yokEPSS %1

    properfraction · profilepress9 Ara 2024

  • CVE-2024-1570
    21İzleyin

    ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    OrtaCVSS 5,4İstismar yokEPSS %0

    properfraction · profilepress28 Şub 2024

  • CVE-2024-1409
    21İzleyin

    Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.0 - Authenticated (Contributor+) S

    OrtaCVSS 5,4İstismar yokEPSS %0

    properfraction · profilepress13 Mar 2024

  • CVE-2024-3210
    21İzleyin

    Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.5 - Authenticated (Contributor+) S

    OrtaCVSS 5,4İstismar yokEPSS %0

    properfraction · profilepress10 Nis 2024

  • CVE-2023-41953
    21İzleyin

    WordPress ProfilePress plugin <= 4.13.1 - Broken Access Control vulnerability

    OrtaCVSS 5,3İstismar yokEPSS %0

    properfraction · profilepress9 Ara 2024

  • CVE-2023-23820
    21İzleyin

    WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)

    OrtaCVSS 5,4İstismar yokEPSS %0

    properfraction · profilepress3 May 2023

  • CVE-2024-11083
    21İzleyin

    ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

    OrtaCVSS 5,3İstismar yokEPSS %0

    properfraction · profilepress27 Kas 2024

  • CVE-2024-2867
    21İzleyin

    Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.4 - Authenticated (Contributor+) S

    OrtaCVSS 5,4İstismar yokEPSS %0

    properfraction · profilepress2 May 2024

  • CVE-2024-1046
    21İzleyin

    Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.3 - Authenticated (Contributor+) S

    OrtaCVSS 5,4İstismar yokEPSS %0

    properfraction · profilepress5 Şub 2024

  • CVE-2024-2861
    21İzleyin

    ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget

    OrtaCVSS 5,4İstismar yokEPSS %0

    properfraction · profilepress23 May 2024